Meta 19
- Internal Paths/Files Leakage via Malformed Access Token on graph.meta.ai
- IDOR - Unauthorized Meta Verified Waitlist Modification
- Toggle Messaging Notification for Any Meta Horizon Account
- Exposes Private Facebook/Workplace Videos for any user
- Page Insight Can Add Questions to Pages
- Business Suite (Paid Partnership) - Add Creator to Any Instagram Account
- Mark Marketplace Item as Paid as a Buyer
- Join Workplace Without Approval of Workplace Admin
- Delete Any Ads Reporting Preview Shared with Others
- Block Appointments Requests for Any Facebook Page
- View Reports Ad Account for Any Business (Export via Report ID)
- Bypass Pixel Role (Partner Business)
- Business Partner Can Escalate Role on Block Lists
- Takeover any wit.ai account
- View Draft, Archived and Inactive Effects for Any Facebook or Instagram User
- Delete Groups AR Studio Effect
- Disclosing Private Group Members via Facebook Rooms
- Disclose Page Admins via Facebook Appointments
- View Pending Email of Any Oculus User via GraphQL